Senior Hardware Security Engineer

Lime Lime · Consumer · Canada · Engineering

Senior Hardware Security Engineer responsible for hardware and firmware security architecture, threat modeling, risk assessment, security testing, firmware hardening, incident response, and compliance for embedded systems in a micromobility product portfolio.

What you'd actually do

  1. Contribute to hardware security architecture reviews for product platforms, providing security input on secure boot chains, hardware roots of trust, trusted execution environments (TEEs), and cryptographic implementations.
  2. Conduct threat modeling exercises for hardware and firmware components, identifying attack surfaces across the product stack.
  3. Perform hands-on security assessments of hardware platforms, including side-channel analysis, fault injection testing, firmware reverse engineering, and debug interface evaluation.
  4. Develop firmware hardening recommendations and work with firmware engineering teams to implement secure boot, firmware update integrity, tamper detection and runtime protection mechanisms across product platforms.
  5. Participate in incident response efforts for hardware and firmware security incidents, contributing to investigation, root-cause analysis, and corrective action to prevent recurrence.

Skills

Required

  • 5+ years of experience in a dedicated hardware or firmware security engineering role
  • Strong focus on embedded systems, platform security, or product security
  • Expertise across hardware security domains
  • Strong proficiency in at least one or two specialized sub-disciplines: Firmware security (Secure boot, TEEs, firmware integrity, secure update mechanisms) OR Platform security (Hardware root of trust, TPM/secure enclaves, cryptographic)

Nice to have

  • Experience in a fast-paced, lean, and remote-first company
  • Proactive problem-solver
  • Passionate about building scalable and robust security solutions
  • Experience with confidential computing
  • Experience with post-quantum cryptographic hardware
  • Experience with hardware-backed attestation
  • Experience with side-channel analysis
  • Experience with fault injection testing
  • Experience with firmware reverse engineering
  • Experience with debug interface evaluation
  • Experience with automated security tooling
  • Experience with vulnerability scanning
  • Experience with compliance validation
  • Experience with security gates within CI/CD and build pipelines for firmware
  • Experience with NIST SP 800-193
  • Experience with Common Criteria
  • Experience with FIPS 140
  • Experience with IEC 62443
  • Experience with product security certifications
  • Experience with compliance efforts
  • Experience with supply chain security concerns
  • Experience with regulatory requirements
  • Experience with UEFI
  • Experience with BMC
  • Experience with TPM interactions

What the JD emphasized

  • hardware security program
  • embedded systems
  • physical products
  • hardware security architecture reviews
  • secure boot chains
  • hardware roots of trust
  • trusted execution environments (TEEs)
  • cryptographic implementations
  • silicon and SoC security properties
  • firmware hardening recommendations
  • secure boot
  • firmware update integrity
  • tamper detection
  • runtime protection mechanisms
  • embedded systems
  • microcontrollers
  • platform firmware
  • hardware-software interfaces
  • UEFI
  • BMC
  • TPM interactions
  • side-channel analysis
  • fault injection testing
  • firmware reverse engineering
  • debug interface evaluation
  • hardware security testing methodology
  • lab environment
  • automated and repeatable assessments
  • vulnerability management
  • hardware and firmware components
  • disclosure
  • remediation tracking
  • validation of fixes
  • firmware hardening recommendations
  • secure boot
  • firmware update integrity
  • tamper detection
  • runtime protection mechanisms
  • embedded systems
  • microcontrollers
  • platform firmware
  • hardware-software interfaces
  • UEFI
  • BMC
  • TPM interactions
  • incident response
  • hardware and firmware security incidents
  • investigation
  • root-cause analysis
  • corrective action
  • automated security tooling
  • hardware and firmware analysis
  • vulnerability scanning
  • compliance validation
  • security gates
  • CI/CD
  • build pipelines for firmware
  • automated enforcement
  • hardware security standards
  • policies
  • procedures
  • NIST SP 800-193
  • Common Criteria
  • FIPS 140
  • IEC 62443
  • product security certifications
  • compliance efforts
  • hardware security attestation
  • hardware threat landscape
  • supply chain security concerns
  • regulatory requirements
  • hardware security
  • engineering peers
  • junior team members'
  • hardware security skills
  • assessment reviews
  • design reviews
  • hardware security best practices
  • hardware security threats
  • technologies
  • best practices